Repository navigation
EntraID OAuth support. #846
Description
Activity
I think it's important to point out that Entra doesn't guarantee an email claim to be returned, even if the permission is granted in the app registration.
Based on my limited understanding, it's likely the user configured in the original linked issue didn't have a mail address. Entra ID treats mail as a separate field to UPN, and they're often confused.
From MS docs:
...the Microsoft identity platform produces the name claims, subject claim, and email when available and consented to.
The key point here is "when available". Just to double check, does your user have the mail filed populated? Are you able to set up a test user without a mail address to see if we can reproduce the behaviour?
for Work / School accounts, it's true that you don't have to be licensed and you won't receive an email attribute on your user object. There is plenty of documentation online to pass the UPN parameter through to the email token during the auth flow. This is the common failure mode for accounts that don't have email address. UPN is required
https://community.auth0.com/t/entra-ad-users-without-email-cannot-accept-organization-invite/199740/5There's a few other places this is documented online. I would be happy to write the steps and have it included with TinyAuth as an option. I hate seeing EntraID is not supported because it will easily turn people off from using TinyAuth.
Quick update on this. With #1087 you will be able to do claim mapping. This means that you can use irregular claims from the user-info endpoint. For example, if Entra returns
foo_emailin user-info, you can use the following configuration option:TINYAUTH_OAUTH_PROVIDERS_ENTRAID_CLAIMS_EMAIL=foo_email
and Tinyauth will get the email from the
foo_emailclaim. I haven't tested this with Entra and this is as far as I am willing to go with supporting it. This option (and the rest for groups, username and name) is not just for Entra but for any OpenID Connect provider that mostly implements the specification.
I saw this closed issue #26 and the documentation notes here: https://tinyauth.app/docs/reference/authentication. I've been using AzureAD / EntraID for a while now with the following configuration:
EntraID configuration parameters
TINYAUTH_OAUTH_PROVIDERS_GENERIC_CLIENTID=< CLIENTID >
TINYAUTH_OAUTH_PROVIDERS_GENERIC_CLIENTSECRET=< CLIENTSECRET >
TINYAUTH_OAUTH_PROVIDERS_GENERIC_AUTHURL=https://login.microsoftonline.com/< TenantID >/oauth2/v2.0/authorize
TINYAUTH_OAUTH_PROVIDERS_GENERIC_TOKENURL=https://login.microsoftonline.com/< TenantID >/oauth2/v2.0/token
TINYAUTH_OAUTH_PROVIDERS_GENERIC_USERINFOURL=https://graph.microsoft.com/oidc/userinfo
TINYAUTH_OAUTH_PROVIDERS_GENERIC_SCOPES=openid,email,profile
TINYAUTH_OAUTH_PROVIDERS_GENERIC_REDIRECTURL=https://< tinyauth >/api/oauth/callback/generic
TINYAUTH_OAUTH_PROVIDERS_GENERIC_NAME=< your display name >
TINYAUTH_OAUTH_PROVIDERS_GENERIC_INSECURE=false
TINYAUTH_UI_TITLE=< UI NAME >
Here's the metadata for the endpoints too:
https://login.microsoftonline.com//v2.0/.well-known/openid-configuration
offline_access isn't needed in this case, but the automation I have in place to build service principles / app registrations adds it automatically.
This is a standard configuration for EntraID Oauth2 support. Honestly, I don't even think i've seen the debug logs on TinyAuth so I could be way off here, and I apologize for opening up an issue to bring it up if that's the case. I'm happy to help document this out to have it included, or get a EntraID tenant set up for TinyAuth testing.